Security audit
Autowriter
Security checks for vulnerabilities and agentic risk
Overview
Autowriter is a disclosed writing workflow that reads user-provided workspace sources and writes notes, drafts, and logs without evidence of hidden execution or data export.
Install this only in workspaces where the source material may be read and summarized. Review or delete generated research_facts.md, article drafts, and draft logs if they contain sensitive information, and disclose AI assistance where your school, employer, publication, or audience expects it.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
